fix: technically filter THOR checking for BlueKeep vuln

This commit is contained in:
phantinuss
2022-06-28 17:25:50 +02:00
parent 6709a2dbaf
commit b4bce46c65
@@ -7,7 +7,7 @@ references:
- https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES/blob/master/Command%20and%20Control/DE_RDP_Tunnel_5156.evtx
author: Samir Bousseaden
date: 2019/02/16
modified: 2021/07/06
modified: 2022/06/29
tags:
- attack.defense_evasion
- attack.command_and_control
@@ -32,8 +32,11 @@ detection:
SourceAddress:
- '127.*'
- '::1'
condition: selection and ( sourceRDP or destinationRDP )
filter_thor: # checking BlueKeep vulnerability
Application|endswith:
- '\thor.exe'
- '\thor64.exe'
condition: selection and ( sourceRDP or destinationRDP ) and not 1 of filter*
falsepositives:
- Programs that connect locally to the RDP port
- THOR APT scanner (checking BlueKeep vulnerability)
level: high